DEV Community

[Comment from a deleted post]
Collapse
 
sqlrob profile image
Robert Myers

Don't ever generate sql statements from strings, you're leaving yourself vulnerable to sql injection. Use parameterized queries.